Executive brief
Photonic Gallery & Lightbox is a WordPress plugin used to display photos from external services like Flickr and SmugMug. A security vulnerability allows users with 'Contributor' level access to inject malicious scripts into the website. If a site administrator or visitor views the affected content, these scripts could redirect users to malicious sites, display unauthorized advertisements, or compromise the viewer's session.
Technical details
The Photonic Gallery & Lightbox plugin for WordPress (versions 3.33 and below) is vulnerable to Stored Cross-Site Scripting (XSS) due to improper input sanitization and output escaping. An attacker with Contributor-level privileges can inject arbitrary JavaScript payloads into gallery settings or content. The vulnerability requires a victim (such as an administrator) to interact with the affected page for the script to execute in their browser context. This can lead to session hijacking or unauthorized actions performed on behalf of the victim. The issue is addressed in version 3.34.
Affected products
- Sayontan Sinha Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33
Timeline
- 2026-07-13: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-27: advisory: NVD and Patchstack published advisory details
- 2026-07-27: patched: Version 3.34 released to address the vulnerability